Citrix NetScaler төхөөрөмжүүдэд илэрсэн шинэ эмзэг байдал кибер халдлагын эрсдэлийг нэмэгдүүлэв

Published:

Энэхүү мэдээ, нийтлэлийг хиймэл оюун боловсруулав.

SAML нэвтрэлтийн системд нөлөөлөх энэхүү шинэ цоорхой нь үйлчилгээг зогсоох эрсдэлтэй тул хэрэглэгчдийг яаралтай шинэчлэлт хийхийг уриаллаа

Citrix NetScaler ADC болон Gateway төхөөрөмжүүдэд санах ойн хэтрэлт үүсгэж, улмаар үйлчилгээг зогсоох (Denial of Service) аюултай CVE-2026-88779 эмзэг байдал илэрлээ. Энэхүү цоорхой нь SAML (Security Assertion Markup Language) нэвтрэлтийн систем ашигладаг тохиргоотой төхөөрөмжүүдэд нөлөөлж байгаа бөгөөд халдлага үйлдэгчид үүнийг аль хэдийн ашиглаж эхэлснийг аюулгүй байдлын судлаачид болон албаны эх сурвалжууд баталж байна.

Баасан гарагт асуудал илэрснээс хойш Citrix компани шалгалт явуулж, Бямба гарагийн орой гэхэд холбогдох засваруудыг гаргажээ. Тус компани NetScaler-ийн хэрэглэгчдийг шинэчлэгдсэн хувилбарыг нэн даруй суулгахыг зөвлөсөн байна. АНУ-ын Кибер аюулгүй байдал, дэд бүтцийн аюулгүй байдлын агентлаг (CISA) уг эмзэг байдлыг идэвхтэй ашиглаж байгааг баталгаажуулж, холбооны агентлагуудад Лхагва гараг гэхэд засвар хийхийг үүрэг болголоо.

WatchTowr компанийн аюулгүй байдлын шинжээч Жейк Ноттын мэдээлснээр, уг цоорхойг маш энгийн аргаар буюу тусгайлан бэлтгэсэн ганц хүсэлтээр идэвхжүүлж, төхөөрөмжийг ажиллагаагүй болгох боломжтой аж. Энэхүү эмзэг байдал нь өмнө нь илэрсэн найман цоорхойтой техникийн хувьд холбоогүй ч, халдлага үйлдэгчид үүнийг бусад төрлийн халдлагыг хурдасгах зорилгоор ашиглаж байж болзошгүй гэж үзэж байна.

Citrix компани халдлагад өртсөн төхөөрөмжүүдийг шалгах зориулалттай илрүүлэгч скриптийг хэрэглэгчдэд хүргүүлсэн байна. Гэсэн хэдий ч аюулгүй байдлын багууд SAML нэвтрэлт идэвхтэй байгаа Gateway болон AAA виртуал серверүүдийг нэн тэргүүнд шинэчлэх, эсвэл түр зуурын хамгаалалтын тохиргоог хийх шаардлагатай байгааг мэргэжилтнүүд онцоллоо.

Дэлгэрэнгүйг эх сурвалжаас харах

↓Эх сурвалжийг нээх ↓

The attackers just keep coming after Citrix NetScaler appliances, as both the feds and private security researchers warn that someone found – and has already exploited – yet another Citrix bug before it had a patch. This latest vulnerability, tracked as CVE-2026-88779, is a memory overflow bug that leads to denial of service attacks. It only affects NetScaler ADC and Gateway appliances configured as a SAML (Security Assertion Markup Language) service provider or identity provider, used for single sign-on authentication. Late Friday, amid exploitation reports, Citrix confirmed that it was investigating a “newly observed issue related to SAML authentication in customer-managed NetScaler deployments.” By Saturday night, the vendor released a security advisory for NetScaler ADC and NetScaler Gateway with patches, urging vulnerable customers to “install the relevant updated versions as soon as possible.” Citrix also posted a blog about the vulnerability, confirming that it has observed targeted attacks on unmitigated NetScaler deployments that can lead to denial of service. Citrix did not answer our questions about CVE-2026-88779 – including how many instances have been affected and what attackers are doing after exploiting the bug – but urged customers to “quickly apply” the fix to NetScaler instances. “We were recently alerted to a new issue that affects service availability for some NetScaler deployments,” a Citrix spokesperson told The Register. “After we were alerted to this issue we immediately developed and published a mitigation while concurrently developing, testing and deploying a fix.” On Sunday, the US Cybersecurity and Infrastructure Security Agency (CISA) confirmed CVE-2026-88779 was under active exploitation and ordered federal agencies to patch the bug by Wednesday. While the new vulnerability is not technically related to the earlier eight CVEs finally disclosed by Citrix on September 27 – weeks after miscreants began abusing two of these security holes (CVE-2026-88772 and CVE-2026-88771) – watchTowr researchers told us they suspect it has been used to purposefully crash machines, making exploitation of CVE-2026-88771 faster. “This vulnerability is incredibly simple to trigger, with a single specially crafted request being all that is needed to knock an appliance offline,” watchTowr’s head of threat intelligence, Jake Knott, told The Register. “Exploitation is already occurring in the wild, and disrupting an authentication gateway can prevent legitimate users from accessing the services behind it.” WatchTowr reproduced the vulnerability on Friday, and Citrix credited the attack-surface management company along with Bishop Fox with helping it address the issue. “Citrix provides an indicator-of-compromise script that teams can run to check exposed appliances for signs of compromise, though a clean result is not definitive proof,” Knott said. “Security teams should prioritize appliances configured as a Gateway or AAA virtual server with SAML authentication enabled, and affected organizations should apply the fixed build or Citrix’s interim mitigation if an immediate upgrade is not possible.”®

Та юу гэж бодож байна?

Сэтгэгдлээ оруулна уу!
Please enter your name here

MFC.mn сайтад сэтгэгдэл оруулахад анхаарах зүйлс

Холбоотой

spot_img

Шинэ

spot_img